MOTG.

Dropit
Privacy Policy

Dropit — Drop anything. It'll be there when you need it.

Last updated: October 3, 2026

Dropit
개인정보처리방침

Dropit — 던져두세요. 찾아드릴게요. 잊지 않을게요.

최종 수정일: 2026년 10월 3일

In short

Dropit saves the links, memos, and notes you choose to send it, and gives them back when you need them. We handle only what is needed to keep your archive working: your account identifier, the content you submit, and the metadata needed to categorize it. We do not sell your data, use it for personalized advertising, or pass it to data brokers.

1. Scope

Dropit is a personal archiving service operated by MOTG through the Dropit Chrome Extension, Telegram Bot and Mini App, and web app. This policy describes the data handled by those interfaces.

2. Data we handle

Account and authentication data

  • Telegram platform account identifiers.
  • Historical KakaoTalk platform account identifiers linked before KakaoTalk support ended on October 3, 2026. Dropit no longer collects new KakaoTalk data.
  • Google account ID, verified email address, and, when available, display name. Dropit does not use an email address to automatically merge accounts. Cross-platform linking requires the user's explicit code-based action.
  • An internal Dropit user identifier.
  • One-time linking codes and signed authentication tokens.
  • In the web app, Google email and display name may be stored in the browser for account display. The server uses the Google account ID to maintain the account link.

Content and browser data

  • URLs, text memos, to-dos, search terms, categories, favorites, reminders, and settings that the user chooses to submit.
  • For the Chrome Extension, the current page URL and title are read so the side panel can show the page. They are sent to the Dropit server only when the user chooses Save this page.
  • Page title, description, thumbnail, transcript or page text needed to classify and summarize a saved link.
  • AI-generated categories, summaries, and weekly reports.

Local storage and operational data

  • The extension stores the signed authentication token and theme preference in Chrome local storage. Short-lived interface state may use Chrome session storage.
  • The web app uses browser local or session storage for its signed token, display preferences, and Google account display information.
  • Hosting and infrastructure providers may process request metadata such as IP address, date/time, user agent, error information, and limited account/content identifiers or saved-URL excerpts written by the service in operational logs.
  • The website loads Google Analytics and Microsoft Clarity. Google Analytics receives an internal Dropit user ID or Telegram user ID when available, a platform label, page/app activity, feature events, tab names, and the complete saved URL when a bookmark is opened from the web app, together with standard browser and request metadata. Microsoft Clarity may process page views, session interactions, and device/browser or similar technical identifiers according to its script and project configuration. These services may use cookies or comparable browser identifiers.

Dropit does not collect contacts, address books, precise location, payment information, financial information, health information, or passwords. The extension package itself does not embed analytics scripts or call Google Analytics or Microsoft Clarity directly. If a user opens the full Dropit archive from the extension, the separately loaded Dropit website uses the analytics described above and labels that web session as originating from the extension.

3. How we use data

We use data only to:

  • authenticate the user and keep accounts separated;
  • save, organize, search, display, and synchronize the user's archive;
  • fetch metadata and create AI categories or summaries for links the user chose to save;
  • detect duplicate links;
  • link or unlink accounts when the user explicitly requests it;
  • deliver requested bot messages and opted-in weekly reports;
  • maintain security, reliability, and prevent abuse;
  • measure use of the Dropit website and its features; and
  • understand website sessions and interactions.

We do not sell user data, use it for personalized advertising, transfer it to data brokers, or use it for credit or lending decisions.

4. Sharing and processors

We share data only as needed for the purposes described in this policy:

ProviderPurposeData involved
Telegram Bot APIReceive user-submitted messages and send requested bot responsesTelegram account ID and submitted messages
Google Identity ServicesVerify a Google sign-in selected by the userGoogle sign-in credential and account claims
SupabaseStore and query Dropit account and archive dataInternal/platform identifiers, saved content, metadata, settings, reports
GroqGenerate AI classification and summariesSaved URL, title, metadata, transcript or page text, or memo text needed for the requested result
VercelHost the web app and server functionsRequests, responses, IP address and operational logs
Google AnalyticsMeasure use of the Dropit website and its featuresInternal or Telegram user ID when available, platform label, page/app and feature events, tab names, opened bookmark URL, and technical/browser metadata
Microsoft ClarityUnderstand website sessions and interactionsPage views, session interactions, and technical/browser identifiers as determined by the Clarity script and project configuration

Each provider processes data under its own terms and privacy policy. Dropit does not use these analytics integrations for personalized advertising or sale of user data.

5. Account linking

Account linking is voluntary. A linking code becomes unusable after 5 minutes and is single-use. Used, replaced, or explicitly checked expired codes are removed, but Dropit does not currently run a separate automatic deletion schedule for untouched expired code rows. A code links the identities selected by the user; Dropit does not automatically merge accounts by matching email address. Unlinking does not automatically delete archived content.

6. Authentication lifetime and storage

  • Standard signed tokens expire after 24 hours.
  • Long-lived tokens used by the Chrome Extension and web sign-in expire after 30 days.
  • Tokens are self-contained signed credentials and are not stored as plaintext passwords in the Dropit database.
  • An extension token can remain in Chrome local storage until logout, extension data removal, or replacement, but the server rejects it after its signed expiry.
  • Saved archive data has no automatic expiry. It remains until the user deletes individual items or submits a verified account-deletion request to MOTG; account deletion is currently handled as a manual support process.
  • Historical KakaoTalk identifiers and content submitted through the former integration follow the same retention and deletion rules above.
  • Provider operational logs are retained under the applicable provider configuration and policy.
  • Google Analytics and Microsoft Clarity retention periods are not specified in this repository, and the live project retention settings were not verified for this release. Their records remain subject to the operator's configured settings and each provider's policy; no automatic deletion period is promised here.

7. Security

User data is transmitted over HTTPS. Database and service credentials are restricted to server-side configuration. Dropit validates signed tokens, uses time-limited single-use account-linking codes, and limits server-side URL fetching to public network addresses. No method of storage or transmission is completely risk-free.

8. User choices and rights

Users may request access, correction, export, deletion, or account unlinking by contacting MOTG. The service may ask for reasonable identity verification before acting on a request. Deleting the extension removes its local browser storage; it does not by itself delete server-side archive data.

9. Chrome Web Store Limited Use

The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.

Data obtained through Chrome Extension permissions is used only to provide or improve Dropit's single purpose: letting the user save and retrieve web pages in their personal archive. We do not allow humans to read that data except with the user's explicit consent for support, when necessary for security, when required by law, or after aggregation and anonymization for lawful internal operations.

10. Children

Dropit is not intended for children under 13, and MOTG does not knowingly collect their data.

11. Changes

If data practices change, this policy and any required in-product or store disclosures will be updated before the changed collection begins.

12. Contact

핵심 요약

Dropit은 사용자가 보낸 링크·메모·할 일을 보관했다가 필요할 때 다시 찾아주는 개인 아카이빙 서비스입니다. 보관함이 동작하는 데 필요한 정보 — 계정 식별자, 사용자가 직접 보낸 내용, 분류에 필요한 메타데이터 — 만 처리합니다. 개인정보를 판매하거나, 맞춤형 광고에 쓰거나, 데이터 브로커에 넘기지 않습니다.

1. 적용 범위

Dropit은 MOTG가 운영하는 개인 아카이빙 서비스로, Dropit 크롬 확장 프로그램, 텔레그램 봇·미니앱, 웹앱을 통해 제공됩니다. 이 방침은 위 인터페이스에서 처리되는 정보를 설명합니다.

2. 처리하는 정보

계정·인증 정보

  • 텔레그램 플랫폼 계정 식별자
  • 2026년 10월 3일 카카오톡 지원 종료 전에 연결된 과거 카카오톡 플랫폼 계정 식별자. Dropit은 더 이상 새로운 카카오톡 데이터를 수집하지 않습니다.
  • Google 계정 ID, 인증된 이메일 주소, 제공되는 경우 표시 이름. Dropit은 이메일 주소가 같다는 이유로 계정을 자동 병합하지 않으며, 플랫폼 간 연동은 사용자가 직접 코드를 입력해야 이루어집니다.
  • Dropit 내부 사용자 식별자
  • 일회용 연동 코드와 서명된 인증 토큰
  • 웹앱에서는 계정 표시를 위해 Google 이메일과 표시 이름이 브라우저에 저장될 수 있습니다. 서버는 계정 연결 유지를 위해 Google 계정 ID를 사용합니다.

콘텐츠·브라우저 정보

  • 사용자가 직접 보낸 URL, 텍스트 메모, 할 일, 검색어, 카테고리, 즐겨찾기, 리마인더, 설정
  • 크롬 확장 프로그램은 사이드 패널에 현재 페이지를 표시하기 위해 페이지 URL과 제목을 읽습니다. 이 정보는 사용자가 이 페이지 저장을 선택할 때만 Dropit 서버로 전송됩니다.
  • 저장된 링크를 분류·요약하는 데 필요한 페이지 제목, 설명, 썸네일, 자막 또는 본문 텍스트
  • AI가 생성한 카테고리, 요약, 주간 리포트

로컬 저장·운영 정보

  • 확장 프로그램은 서명된 인증 토큰과 테마 설정을 크롬 로컬 스토리지에 저장합니다. 일시적인 화면 상태는 크롬 세션 스토리지를 사용할 수 있습니다.
  • 웹앱은 서명된 토큰, 화면 설정, Google 계정 표시 정보를 브라우저 로컬·세션 스토리지에 저장합니다.
  • 호스팅·인프라 제공자는 IP 주소, 일시, 사용자 에이전트, 오류 정보, 서비스가 운영 로그에 기록한 제한적인 계정·콘텐츠 식별자나 저장 URL 일부 같은 요청 메타데이터를 처리할 수 있습니다.
  • 웹사이트는 Google Analytics와 Microsoft Clarity를 불러옵니다. Google Analytics는 가능한 경우 Dropit 내부 사용자 ID 또는 텔레그램 사용자 ID, 플랫폼 구분값, 페이지·앱 사용 내역, 기능 이벤트, 탭 이름, 웹앱에서 북마크를 열 때의 전체 저장 URL과 함께 일반적인 브라우저·요청 메타데이터를 전달받습니다. Microsoft Clarity는 스크립트와 프로젝트 설정에 따라 페이지 조회, 세션 내 상호작용, 기기·브라우저 등 기술적 식별자를 처리할 수 있습니다. 이들 서비스는 쿠키나 유사한 브라우저 식별자를 사용할 수 있습니다.

Dropit은 연락처, 주소록, 정밀 위치, 결제 정보, 금융 정보, 건강 정보, 비밀번호를 수집하지 않습니다. 확장 프로그램 패키지 자체에는 분석 스크립트가 포함되어 있지 않으며 Google Analytics나 Microsoft Clarity를 직접 호출하지 않습니다. 확장 프로그램에서 전체 보관함을 열면 별도로 로드되는 Dropit 웹사이트가 위 분석 도구를 사용하며, 해당 세션은 확장 프로그램에서 시작된 것으로 표시됩니다.

3. 이용 목적

수집한 정보는 다음 목적으로만 사용합니다.

  • 사용자 인증 및 계정 분리
  • 보관함의 저장·정리·검색·표시·동기화
  • 사용자가 저장하기로 선택한 링크의 메타데이터 수집과 AI 카테고리·요약 생성
  • 중복 링크 감지
  • 사용자가 명시적으로 요청한 계정 연동·해제
  • 요청한 봇 메시지와 수신 동의한 주간 리포트 발송
  • 보안·안정성 유지 및 악용 방지
  • Dropit 웹사이트와 기능의 사용량 측정
  • 웹사이트 세션·상호작용 파악

개인정보를 판매하거나, 맞춤형 광고에 이용하거나, 데이터 브로커에 이전하거나, 신용·대출 판단에 사용하지 않습니다.

4. 제3자 제공과 처리위탁

이 방침에 기재된 목적에 필요한 범위에서만 정보를 공유합니다.

처리자목적전송 항목
Telegram Bot API사용자가 보낸 메시지 수신 및 요청한 봇 응답 발송텔레그램 계정 ID, 전송한 메시지
Google Identity Services사용자가 선택한 Google 로그인 검증Google 로그인 자격 증명과 계정 클레임
SupabaseDropit 계정·보관함 데이터 저장과 조회내부·플랫폼 식별자, 저장 콘텐츠, 메타데이터, 설정, 리포트
GroqAI 분류·요약 생성결과 생성에 필요한 저장 URL, 제목, 메타데이터, 자막·본문 텍스트 또는 메모 텍스트
Vercel웹앱과 서버 함수 호스팅요청·응답, IP 주소, 운영 로그
Google AnalyticsDropit 웹사이트와 기능의 사용량 측정가능한 경우 내부·텔레그램 사용자 ID, 플랫폼 구분값, 페이지·앱 및 기능 이벤트, 탭 이름, 열람한 북마크 URL, 기술·브라우저 메타데이터
Microsoft Clarity웹사이트 세션·상호작용 파악Clarity 스크립트와 프로젝트 설정에 따른 페이지 조회, 세션 상호작용, 기술·브라우저 식별자

각 제공자는 자체 약관과 개인정보처리방침에 따라 정보를 처리합니다. Dropit은 이 분석 도구를 맞춤형 광고나 개인정보 판매에 사용하지 않습니다.

5. 계정 연동

계정 연동은 선택 사항입니다. 연동 코드는 5분이 지나면 사용할 수 없고 1회만 쓸 수 있습니다. 사용·교체되었거나 만료가 확인된 코드는 삭제되지만, 아무도 건드리지 않은 만료 코드 행에 대한 별도의 자동 삭제 일정은 현재 운영하지 않습니다. 코드는 사용자가 선택한 계정끼리만 연결하며, 이메일 주소가 같다는 이유로 계정을 자동 병합하지 않습니다. 연동을 해제해도 보관된 콘텐츠가 자동으로 삭제되지는 않습니다.

6. 인증 유효기간과 보관

  • 일반 서명 토큰은 24시간 후 만료됩니다.
  • 크롬 확장 프로그램과 웹 로그인에 사용되는 장기 토큰은 30일 후 만료됩니다.
  • 토큰은 자체 완결형 서명 자격 증명이며, Dropit 데이터베이스에 평문 비밀번호로 저장되지 않습니다.
  • 확장 프로그램 토큰은 로그아웃·데이터 삭제·교체 전까지 크롬 로컬 스토리지에 남을 수 있지만, 서명된 만료 시각이 지나면 서버가 거부합니다.
  • 저장된 보관함 데이터에는 자동 만료가 없습니다. 사용자가 개별 항목을 삭제하거나 본인 확인을 거친 계정 삭제를 MOTG에 요청할 때까지 유지되며, 계정 삭제는 현재 수동 지원 절차로 처리됩니다.
  • 이전 카카오톡 연동을 통해 제출된 과거 식별자와 콘텐츠에는 위와 같은 보관·삭제 기준이 적용됩니다.
  • 제공자의 운영 로그는 해당 제공자의 설정과 정책에 따라 보관됩니다.
  • Google Analytics와 Microsoft Clarity의 보관 기간은 이 저장소에 명시되어 있지 않으며, 이번 배포를 위해 실제 프로젝트의 보관 설정을 확인하지는 않았습니다. 해당 기록은 운영자가 설정한 값과 각 제공자의 정책을 따르며, 이 방침에서 자동 삭제 기간을 약속하지 않습니다.

7. 보안

사용자 데이터는 HTTPS로 전송됩니다. 데이터베이스와 서비스 자격 증명은 서버 측 설정으로 제한됩니다. Dropit은 서명 토큰을 검증하고, 시간 제한이 있는 일회용 연동 코드를 사용하며, 서버 측 URL 조회를 공개 네트워크 주소로 제한합니다. 다만 어떤 저장·전송 방식도 위험이 전혀 없다고 할 수는 없습니다.

8. 사용자의 선택과 권리

사용자는 MOTG에 연락해 열람, 정정, 내보내기, 삭제, 계정 연동 해제를 요청할 수 있습니다. 요청 처리 전에 합리적인 본인 확인을 요청할 수 있습니다. 확장 프로그램을 삭제하면 브라우저에 저장된 로컬 데이터는 제거되지만, 그것만으로 서버의 보관함 데이터가 삭제되지는 않습니다.

9. Chrome 웹 스토어 제한적 사용

Google API로부터 받은 정보의 이용은 제한적 사용(Limited Use) 요건을 포함한 Chrome 웹 스토어 사용자 데이터 정책을 준수합니다.

크롬 확장 프로그램 권한을 통해 얻은 데이터는 Dropit의 단일 목적 — 사용자가 웹페이지를 개인 보관함에 저장하고 다시 찾아보게 하는 것 — 을 제공하거나 개선하는 데에만 사용합니다. 사용자가 지원을 위해 명시적으로 동의한 경우, 보안상 필요한 경우, 법적으로 요구되는 경우, 또는 적법한 내부 운영을 위해 집계·익명화한 경우를 제외하고는 사람이 해당 데이터를 읽지 않습니다.

10. 아동 개인정보

Dropit은 만 13세 미만 아동을 대상으로 하지 않으며, MOTG는 아동의 개인정보를 알면서 수집하지 않습니다.

11. 방침 변경

데이터 처리 방식이 바뀌면, 변경된 수집이 시작되기 전에 이 방침과 필요한 앱 내·스토어 고지를 갱신합니다.

12. 문의